Nessus - how to test your firewall access and performance

Submitted by Patrick Grote on Mon, 08/07/2006 - 7:29pm.

We start the walk through the eWeek top 25 technologies in the last 25 years with a look at Nessus, which came in at number 25. For those who don't know, Nessus was started as a free project in 1998 as a way for people to test vulnerabilities through scanning.

Nessus is software that scans the ports on your network and will report back any vulnerabilities. The beauty of the software is in its ability to use plug-ins created by other users. These plug-ins allow you to scan for other vulnerabilities and adds functionality to the base product. I don't remember where I first heard about Nessus, but I do remember the first time I used it.

Working as a contractor, I was hired by a large travel company to work on their web side of the house. The position was interesting, and very technical since the web was so new and using it on a large scale was pretty much unknown.

One of the projects I was assigned to provided technical services to the web development team. They were busy working on a registration system for Novell's Brainshare program. Brainshare is an annual meeting for people who have been certified in Novell programs. At the time, you needed to be a Certified Netware Engineer to attend.

The web development team was responsible for the registration program, which then handled travel planning in the background. It was a pretty big product, as this service was part and parcel of the overall travel account for Novell.

In various meetings the web development team noticed that our servers inside the DMZ were having issues and they suspected that someone was finding a way into the Netscape servers. I thought this was a great chance to use Nessus and see if it could help us.

We didn't find anything out of the ordinary for our servers, but we did find open ports for the email servers in the DMZ. Nessus helped identify them and close them down.

Do I think it's a top 25 in the last 25 years. Probably not, but I do see where eWeek was going with this. Nessus was the first community involved security product for internet infrastructure.


add new comment | 767 reads